CWE-296 · 14 записей
Improper Following of a Certificate's Chain of Trust
CVE этого класса
14 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
37Наблюдать | CVE-2025-48057Эксплойта нет | Icinga 2 certificate renewal might incorrectly renew an invalid certificateicinga · icinga · CWE-296 | Критическая9,3 | — | 0,4 % | 27 мая 2025 г. |
37Наблюдать | CVE-2026-96770Эксплойта нет | s2s-proxy accepts untrusted client certificatestemporal technologies, inc. · s2s-proxy · CWE-296 | Критическая9,3 | — | 0,3 % | 23 сент. 2026 г. |
33Наблюдать | CVE-2026-33779Эксплойта нет | Junos OS: SRX Series: Insufficient certificate verification for device to SD cloud communicationjuniper · junos · CWE-296 | Высокая8,3 | — | 0,2 % | 9 апр. 2026 г. |
33Наблюдать | CVE-2026-24066Эксплойта нет | Slate Digital Connect macOS XPC certificate validation privilege escalationslate digital llc · slate digital connect · CWE-296 | Высокая8,4 | — | 0,1 % | 10 июн. 2026 г. |
32Наблюдать | CVE-2021-23162Эксплойта нет | Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Cgallagher · command centre mobile connect · CWE-296 | Высокая8,1 | — | 0,4 % | 18 нояб. 2021 г. |
32Наблюдать | CVE-2025-1146Эксплойта нет | CrowdStrike Falcon Sensor for Linux TLS Issuecrowdstrike · falcon sensor for linux · CWE-296 | Высокая8,1 | — | 0,3 % | 12 февр. 2025 г. |
30Наблюдать | CVE-2019-3762Эксплойта нет | Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability.dell · emc data protection central · CWE-296 | Высокая7,5 | — | 0,6 % | 18 мар. 2020 г. |
29Наблюдать | CVE-2021-1566Эксплойта нет | Cisco Email Security Appliance and Cisco Web Security Appliance Certificate Validation Vulnerabilitycisco · email security appliance · CWE-296 | Высокая7,4 | — | 0,7 % | 16 июн. 2021 г. |
28Наблюдать | CVE-2026-44852Эксплойта нет | Authenticated Remote Code Execution via Arbitrary File Overwrite in the AOS-8 and AOS-10 Web-Based Management Interfacearubanetworks · arubaos · CWE-296 | Высокая7,2 | — | 0,6 % | 12 мая 2026 г. |
27Наблюдать | CVE-2021-23155Эксплойта нет | Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Cegallagher · command centre mobile client · CWE-296 | Средняя6,8 | — | 0,5 % | 18 нояб. 2021 г. |
25Наблюдать | CVE-2026-73542Эксплойта нет | Multiple SEIKO EPSON printers and scanners contain revoked root certificates.seiko epson corporation · multiple seiko epson printers and scanners · CWE-296 | Средняя6,3 | — | 0,2 % | 20 авг. 2026 г. |
24Наблюдать | CVE-2021-44532Эксплойта нет | Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format.nodejs · node.js · CWE-296 | Средняя5,3 | — | 10,4 % | 24 февр. 2022 г. |
19Наблюдать | CVE-2025-22459Эксплойта нет | Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticateivanti · endpoint manager · CWE-296 | Средняя4,8 | — | 0,3 % | 8 апр. 2025 г. |
17Наблюдать | CVE-2024-43196Эксплойта нет | IBM OpenPages data manipulationibm · openpages with watson · CWE-296 | Средняя4,3 | — | 0,2 % | 20 февр. 2025 г. |
- CVE-2025-4805737Наблюдать
Icinga 2 certificate renewal might incorrectly renew an invalid certificate
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %icinga · icinga27 мая 2025 г.
- CVE-2026-9677037Наблюдать
s2s-proxy accepts untrusted client certificates
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %temporal technologies, inc. · s2s-proxy23 сент. 2026 г.
- CVE-2026-3377933Наблюдать
Junos OS: SRX Series: Insufficient certificate verification for device to SD cloud communication
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %juniper · junos9 апр. 2026 г.
- CVE-2026-2406633Наблюдать
Slate Digital Connect macOS XPC certificate validation privilege escalation
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %slate digital llc · slate digital connect10 июн. 2026 г.
- CVE-2021-2316232Наблюдать
Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command C
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %gallagher · command centre mobile connect18 нояб. 2021 г.
- CVE-2025-114632Наблюдать
CrowdStrike Falcon Sensor for Linux TLS Issue
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %crowdstrike · falcon sensor for linux12 февр. 2025 г.
- CVE-2019-376230Наблюдать
Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dell · emc data protection central18 мар. 2020 г.
- CVE-2021-156629Наблюдать
Cisco Email Security Appliance and Cisco Web Security Appliance Certificate Validation Vulnerability
ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %cisco · email security appliance16 июн. 2021 г.
- CVE-2026-4485228Наблюдать
Authenticated Remote Code Execution via Arbitrary File Overwrite in the AOS-8 and AOS-10 Web-Based Management Interface
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %arubanetworks · arubaos12 мая 2026 г.
- CVE-2021-2315527Наблюдать
Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Ce
СредняяCVSS 6,8Эксплойта нетEPSS 0 %gallagher · command centre mobile client18 нояб. 2021 г.
- CVE-2026-7354225Наблюдать
Multiple SEIKO EPSON printers and scanners contain revoked root certificates.
СредняяCVSS 6,3Эксплойта нетEPSS 0 %seiko epson corporation · multiple seiko epson printers and scanners20 авг. 2026 г.
- CVE-2021-4453224Наблюдать
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format.
СредняяCVSS 5,3Эксплойта нетEPSS 10 %nodejs · node.js24 февр. 2022 г.
- CVE-2025-2245919Наблюдать
Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticate
СредняяCVSS 4,8Эксплойта нетEPSS 0 %ivanti · endpoint manager8 апр. 2025 г.
- CVE-2024-4319617Наблюдать
IBM OpenPages data manipulation
СредняяCVSS 4,3Эксплойта нетEPSS 0 %ibm · openpages with watson20 февр. 2025 г.